惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏
M
MIT News - Artificial intelligence
腾讯CDC
博客园 - Franky
Engineering at Meta
Engineering at Meta
C
Check Point Blog
T
The Blog of Author Tim Ferriss
有赞技术团队
有赞技术团队
Microsoft Azure Blog
Microsoft Azure Blog
MyScale Blog
MyScale Blog
I
InfoQ
Blog — PlanetScale
Blog — PlanetScale
P
Proofpoint News Feed
The GitHub Blog
The GitHub Blog
N
Netflix TechBlog - Medium
Last Week in AI
Last Week in AI
S
SegmentFault 最新的问题
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
WordPress大学
WordPress大学

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Microsoft 365 Device Code Phishing Campaign Bypasses Pass...
Tushar Subhra Dutta · 2026-06-16 · via Cyber Security News

A new phishing campaign targeting Microsoft 365 users has been uncovered, and it takes a different approach than most attacks seen in the wild.

Instead of trying to steal a victim’s password directly, this campaign tricks users into completing a real Microsoft authentication process that quietly hands over control of their account to an attacker.

It is a convincing technique that is becoming harder for everyday users to recognize. The method at the center of this campaign is called Device Code phishing.

In a normal, legitimate scenario, Microsoft’s Device Code flow helps users authenticate on devices where typing a username and password is inconvenient, such as a smart TV or a command-line tool.

The attacker here has turned that helpful feature into a trap, using it to authorize their own controlled device to access the victim’s account without ever collecting a password.

Analysts at ReversingLabs identified and documented this active campaign, noting that it combines realistic business-themed lure emails, a polished phishing kit, and Microsoft’s own Device Authorization Grant flow to carry out a near-invisible account takeover.

ReversingLabs researchers said in a report, shared with Cyber Security News (CSN), reveals how threat actors have refined this technique to bypass standard defenses and make the attack appear as a routine Microsoft login.

The attack starts with an email that looks like an approval request from a vendor or a business contact. Attached is an image that, when clicked, redirects the victim to a fake landing page mimicking a genuine Microsoft design.

From there, the victim is asked to copy a short code and enter it on the real Microsoft device login page. Most people have no reason to suspect anything unusual at this point.

Device Code phishing lure image (Source - ReversinLabs)
Device Code phishing lure image (Source – ReversinLabs)

Once the code is entered and the victim signs in, Microsoft’s authentication system authorizes the attacker’s device. The victim sees nothing out of the ordinary.

The attacker now holds a valid access token for that Microsoft 365 account and can use it to read emails, access files, and move laterally inside a target organization.

Microsoft 365 Device Code Phishing Campaign

The phishing kit behind this campaign is built to evade automated detection.

The landing pages embed invisible Unicode characters, including Zero Width Space, Word Joiner, and Zero Width Non-Joiner, scattered throughout words that security tools flag as phishing indicators.

Device code phishing landing page (Source - ReversingLabs)
Device code phishing landing page (Source – ReversingLabs)

This makes the pages difficult to catch through standard signature matching. The kit uses a URL hosted on Akamai’s legitimate infrastructure as the device login entry point, adding to its appearance of legitimacy.

A POST request is sent from the kit’s backend to the phishing host every four seconds, coordinating the OAuth flow between the attacker and the authentication session the victim is completing. This steady beacon is one of the few detectable signs of the attack.

Device code POST request to phishing kit host (Source - ReversingLabs)
Device code POST request to phishing kit host (Source – ReversingLabs)

The network traffic produced by the kit can also help with detection. Two sequences of hostname resolutions tied to the phishing landing page and the Microsoft authentication flow form identifiable clusters.

A third cluster is beacon activity sent every four seconds after the first authentication phase begins, giving security teams a reliable signal to hunt for in their network logs.

Defending Against Device Code Phishing

ReversingLabs has released a YARA rule to detect the landing pages used by this phishing kit.

The rule identifies combinations of invisible Unicode characters alongside encoded authentication token artifacts in page source code.

When paired with network-based hunting using the traffic patterns described in the report, defenders have a strong starting point.

Organizations should train employees to question any prompt asking them to copy and paste a code into a Microsoft login page.

Monitoring Entra ID sign-in logs for Device Code grant usage is recommended, especially where the sign-in originates from an endpoint that is not a known IoT or command-line device.

Security teams should deploy detections for phishing kit artifacts outlined in the ReversingLabs report, including landing page indicators and the network traffic pattern tied to this attack.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
URLhxxp[://]ajz-gud[.]lisa-g-h-rn[.]workers[.]dev/Phishing kit landing page
URLhxxp[://]baquelite[.]ventoraco[.]com/doc98374/Phishing kit landing page
URLhxxp[://]biotechgroup[.]p-oye8mc0f[.]workers[.]dev/Phishing kit landing page
URLhxxp[://]bradhallfuel[.]p-oye8mc0f[.]workers[.]dev/Phishing kit landing page
URLhxxp[://]corpexl[.]nl/mq5qh1xj9/Phishing kit landing page
URLhxxp[://]corpexl[.]nl/oii/Phishing kit landing page
URLhxxp[://]corpexl[.]nl/projectorder/Phishing kit landing page
URLhxxp[://]creditora[.]me[.]uk/HPDGassociesPhishing kit landing page
URLhxxp[://]dentalstrategies[.]noventragroup[.]app/dntrategie/Phishing kit landing page
URLhxxp[://]docxfile-share[.]itkljpqn[.]workers[.]dev/Phishing kit landing page
URLhxxp[://]docxfiletxz-share[.]itkljpqn[.]workers[.]dev/Phishing kit landing page
URLhxxp[://]gsbauwu1hsa[.]legalaro[.]com/nmasn/Phishing kit landing page
URLhxxp[://]henriquevieira[.]horizoralabs[.]com/doc49390239/Phishing kit landing page
URLhxxp[://]horizonex[.]it[.]com/confidentialrecord/Phishing kit landing page
URLhxxp[://]horizonex[.]it[.]com/securedocumentPhishing kit landing page
URLhxxp[://]hsecontractors-project[.]sign-ins[.]workers[.]dev/Phishing kit landing page
URLhxxp[://]logvault[.]us/jfkydg4of/Phishing kit landing page
URLhxxp[://]mcagroup[.]horizoralabs[.]com/quote937847/Phishing kit landing page
URLhxxp[://]meeting[.]corpsfileshare[.]com/quarterly/Phishing kit landing page
URLhxxp[://]metroraco[.]com/GroupeBergeron/Phishing kit landing page
URLhxxp[://]metroraco[.]com/Vent/Phishing kit landing page
URLhxxp[://]microsoft-document[.]adhere[.]it[.]com/Adobe-pdf/Phishing kit landing page
URLhxxp[://]molinomerano[.]brieflync[.]nl/order9283/Phishing kit landing page
URLhxxp[://]mysharereport[.]wgmilshyvn[.]workers[.]dev/Phishing kit landing page
URLhxxp[://]onedrive-document[.]adhere[.]it[.]com/sharedproject/Phishing kit landing page
URLhxxp[://]retroactive[.]scalevantaco[.]com/adjustmentsPhishing kit landing page
URLhxxp[://]review[.]wgmilshyvn[.]workers[.]dev/Phishing kit landing page
URLhxxp[://]sales[.]p-ct5v25xo[.]workers[.]dev/Phishing kit landing page
URLhxxp[://]samoen[.]logvault[.]us/engineeringPhishing kit landing page
URLhxxp[://]sparkaxis[.]org/deployment/Phishing kit landing page
URLhxxp[://]tsk1[.]t31208026[.]workers[.]dev/Phishing kit landing page
URLhxxp[://]uboralmaxillofacialsurgery[.]noventragroup[.]app/uboralxillofiaPhishing kit landing page
URLhxxp[://]uegreil[.]taskvault[.]nl/itiwa2Phishing kit landing page
URLhxxp[://]v379ge[.]meetrova[.]nl/p9mxbmz2x/Phishing kit landing page
URLhxxp[://]wpdoi8w[.]elevatecore[.]it[.]com/g4jlitpi/Phishing kit landing page
URLhxxp[://]wylderhotels[.]sparkaxis[.]org/personaljflannigan/Phishing kit landing page
URLhxxp[://]zktxnxlh[.]stratavaco[.]com/snzv8wqPhishing kit landing page
URLhxxps[://]adhere[.]it[.]com/verify/Phishing kit landing page
URLhxxps[://]apexviaco[.]com/code/Phishing kit landing page
URLhxxps[://]corpexl[.]nl/INV/Phishing kit landing page
URLhxxps[://]corpexl[.]nl/PO/Phishing kit landing page
URLhxxps[://]corpexl[.]nl/securee/Phishing kit landing page
URLhxxps[://]covenant[.]it[.]com/Project/Phishing kit landing page
URLhxxps[://]creditora[.]me[.]uk/NorthShore/Phishing kit landing page
URLhxxps[://]docusign-arizonacreativeevents[.]nextvexharbor[.]de/review/Phishing kit landing page
URLhxxps[://]docusign-stlequityhomes[.]nextvexharbor[.]de/review/Phishing kit landing page
URLhxxps[://]fortknox[.]noventragroup[.]app/fortknoxxx/Phishing kit landing page
URLhxxps[://]growthora[.]app/doc/Phishing kit landing page
URLhxxps[://]horizonex[.]it[.]com/confidentialfile/Phishing kit landing page
URLhxxps[://]login[.]growthora[.]app/document/Phishing kit landing page
URLhxxps[://]meeting[.]corpsfileshare[.]com/quarterly/Phishing kit landing page
URLhxxps[://]metroraco[.]com/Desjardinsh/Phishing kit landing page
URLhxxps[://]metroraco[.]com/InnovativePipeline/Phishing kit landing page
URLhxxps[://]momentoraco[.]com/Project-submittal/Phishing kit landing page
URLhxxps[://]momentoraco[.]com/project-document/Phishing kit landing page
URLhxxps[://]my-team-share[.]corpsfileshare[.]com/team/Phishing kit landing page
URLhxxps[://]nexttrail[.]co[.]nl/m365scoft/Phishing kit landing page
URLhxxps[://]onedrive-encrypted-online[.]clearledge[.]me[.]uk/avc8xt/Phishing kit landing page
URLhxxps[://]onedrive-encrypted[.]clearledge[.]me[.]uk/aar0cphl/Phishing kit landing page
URLhxxps[://]onedrive-microsoft[.]adhere[.]it[.]com/securedocument/Phishing kit landing page
URLhxxps[://]payroll[.]vardeno[.]nl/employee/Phishing kit landing page
URLhxxps[://]ringcentral[.]firmtix[.]com/alert/Phishing kit landing page
URLhxxps[://]ringcentral[.]firmtix[.]com/notify/Phishing kit landing page
URLhxxps[://]secure[.]firmtix[.]com/docxPhishing kit landing page
URLhxxps[://]sparkaxis[.]org/delivery/Phishing kit landing page
URLhxxps[://]sparkaxis[.]org/statement/Phishing kit landing page
URLhxxps[://]stratifylabs[.]org/BDAGroup/Phishing kit landing page
URLhxxps[://]stratifylabs[.]org/FACTURE/Phishing kit landing page
URLhxxps[://]teams[.]vardeno[.]nl/fileshared/Phishing kit landing page
URLhxxps[://]trenix[.]nl/alma-resort/Phishing kit landing page
URLhxxps[://]verif[.]futureanchor[.]it[.]com/cloud/Phishing kit landing page
URLhxxps[://]verification[.]futureanchor[.]it[.]com/cardcrosoft/Phishing kit landing page
URLhxxps[://]vmservfill[.]nkydzvws[.]workers[.]dev/Phishing kit landing page
Network Hostnamelogin.microsoftonline.comLegitimate Microsoft authentication endpoint abused in Device Code flow
Network Hostnameaka.ms/deviceloginLegitimate Microsoft device login URL referenced in phishing lures
Network Hostnamelogin.live.com/oauth20_remoteconnect.srfLegitimate Microsoft Live auth endpoint abused in phishing kit
YARA RuleDeviceCode_Phishing_LandingPageHTMLYARA detection rule for Device Code phishing kit landing pages (authored by Malware Utkonos, dated 2026-05-20)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.